
Product Notes Tab & Private Admin Notes for WooCommerce Security & Risk Analysis
wordpress.org/plugins/product-notes-for-woocommerceAdd notes to WooCommerce products.
Is Product Notes Tab & Private Admin Notes for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Product Notes Tab & Private Admin Notes for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "product-notes-for-woocommerce" v3.1.2 exhibits a mixed security posture. While the static analysis shows a limited attack surface with no direct unprotected entry points like unauthenticated AJAX handlers or REST API routes, several concerning code signals indicate potential weaknesses. The presence of the `unserialize` function is a significant red flag, as it can lead to Remote Code Execution if not handled with extreme care and proper input validation. Furthermore, all SQL queries are executed without prepared statements, making the plugin vulnerable to SQL injection attacks. The low percentage of properly escaped output (29%) suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and the single capability check for entry points also indicate insufficient authorization mechanisms in certain areas.
The vulnerability history reveals one past medium-severity CVE related to XSS, which aligns with the static analysis findings of poor output escaping. The fact that there are no currently unpatched vulnerabilities is a positive sign, suggesting that past issues have been addressed. However, the pattern of past vulnerabilities, particularly XSS, combined with the current code signals, points to a recurring need for more robust input sanitization and output escaping practices.
Overall, while the plugin's direct attack surface appears controlled, the internal code quality raises significant concerns. The reliance on potentially dangerous functions like `unserialize`, the lack of prepared statements for SQL, and the prevalent issues with output escaping create substantial security risks. The past XSS vulnerability reinforces these concerns. Developers should prioritize addressing these internal code weaknesses to improve the plugin's security posture.
Key Concerns
- Dangerous function unserialize found
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- No nonce checks
- Medium severity CVE in history
Product Notes Tab & Private Admin Notes for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Product Notes Tab & Private Admin Notes for WooCommerce <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Product Notes Tab & Private Admin Notes for WooCommerce Release Timeline
Product Notes Tab & Private Admin Notes for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Product Notes Tab & Private Admin Notes for WooCommerce Attack Surface
Shortcodes 1
WordPress Hooks 22
Maintenance & Trust
Product Notes Tab & Private Admin Notes for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Product Notes Tab & Private Admin Notes for WooCommerce Alternatives
Product Visibility by User Role for WooCommerce
product-visibility-by-user-role-for-woocommerce
Display WooCommerce products by customer's user role.
Custom Product Tabs Lite for WooCommerce
woocommerce-custom-product-tabs-lite
This plugin extends WooCommerce by allowing a custom product tab to be created with any content.
Product Price by Formula for WooCommerce
product-price-by-formula-for-woocommerce
Set formula for automatic WooCommerce product price calculation.
Product Admin Notes Simple
products-admin-notes-simple
Simple plugin to add an admin notes field to products, nothing complicated just gets the job done!
Compare Products for WooCommerce
compare-products-for-woocommerce
Let your users know which products interest them the most by comparing them.
Product Notes Tab & Private Admin Notes for WooCommerce Developer Profile
64 plugins · 137K total installs
How We Detect Product Notes Tab & Private Admin Notes for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/product-notes-for-woocommerce/includes/js/alg-wc-pn.js/wp-content/plugins/product-notes-for-woocommerce/includes/js/alg-wc-pn.min.js/wp-content/plugins/product-notes-for-woocommerce/includes/js/alg-wc-pn.js/wp-content/plugins/product-notes-for-woocommerce/includes/js/alg-wc-pn.min.jsproduct-notes-for-woocommerce/includes/js/alg-wc-pn.js?ver=product-notes-for-woocommerce/includes/js/alg-wc-pn.min.js?ver=HTML / DOM Fingerprints
alg-wc-pn-private-product-notesalg-wc-pn-public-product-notesdata-private_iddata-public_idalg_wc_pn